[c-nsp] Re:Sh run filter

Jon Lewis jlewis at lewis.org
Tue Feb 7 12:19:15 EST 2006


On Tue, 7 Feb 2006, Kanagaraj Krishna wrote:

>    In Cisco's enable privilege settings, an user can only view the 
> config (interface, routing protocol etc) under "sh run" only if they are 
> permitted to edit those configurations. In my case, i want the user to 
> see the routing information but not configure them. I tried using the 
> router privilege commands together with the tacacs server permissions, 
> but both cannot work together. Once logged in, it follows the routers 
> privilege setting only.Any ideas?

How about setting up rancid and cvsweb to give people access to see the 
configs but not necessarily the ability to modify them?

----------------------------------------------------------------------
  Jon Lewis                   |  I route
  Senior Network Engineer     |  therefore you are
  Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________


More information about the cisco-nsp mailing list